CVE-2025-2536
Description
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS modules layout-taglib/__liferay__/index.js allows remote attackers to inject arbitrary web script or HTML via toastData parameter
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.062
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2025-2565,CVE-2025-2536,CVE-2025-43785 are fixed in Liferay - release.portal.bom 7.4.3.129 | Windows |
| Vulnerabilities CVE-2025-2565,CVE-2025-2536 are fixed in Liferay - release.dxp.bom 3.1 | Windows |
| Vulnerabilities CVE-2025-2565,CVE-2025-2536,CVE-2025-3760,CVE-2025-43735,CVE-2025-43785 are fixed in Liferay - release.dxp.bom 1.13 | Windows |
| Vulnerabilities CVE-2025-2536 are fixed in Liferay - release.dxp.bom 4.0 | Windows |
| Vulnerabilities CVE-2025-2536 are affected in Liferay - release.dxp.bom 2.11 | Windows |
| Vulnerabilities CVE-2025-2565,CVE-2025-2536,CVE-2025-43785 are fixed in Liferay - release.portal.bom for Linux 7.4.3.129 | Linux |
| Vulnerabilities CVE-2025-2565,CVE-2025-2536 are fixed in Liferay - release.dxp.bom for Linux 3.1 | Linux |
| Vulnerabilities CVE-2025-2565,CVE-2025-2536,CVE-2025-3760,CVE-2025-43735,CVE-2025-43785 are fixed in Liferay - release.dxp.bom for Linux 1.13 | Linux |
| Vulnerabilities CVE-2025-2536 are fixed in Liferay - release.dxp.bom for Linux 4.0 | Linux |
| Vulnerabilities CVE-2025-2536 are affected in Liferay - release.dxp.bom for Linux 2.11 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234